Privacy policy
Last updated 6 October 2026
The short version. Keny is a workplace tool for companies. We collect what an account needs to work and what you put into your workspace. We run no advertising, no analytics, no session recording and no tracking cookies. We do not sell personal data, and we have never sold it. Every company that processes data on our behalf is listed on the subprocessors page.
This policy explains what Yoav Cabili, trading as Keny ("Keny", "we"), does with personal data when you use the Keny app at app.keny.io or this website. It is written to meet the UK GDPR, the EU GDPR and the US state privacy laws that apply to a business tool of this kind.
Who the controller is
For your own account data, Keny is the controller.
For the campaign content inside a workspace, the company that owns the workspace is the controller and Keny is a processor acting on its instructions. If your employer or an agency put your details into a Keny workspace, ask them first: we can only act on their instruction for that data. We will always pass your request on to them.
Keny is run from the United Kingdom. Contact: privacy@keny.io.
What we collect
Your account
- Your name, work email address and job-role label.
- Your password, hashed by our authentication provider. Keny's own code never receives or stores a password.
- If you sign in with Google, Microsoft or your company's single sign-on instead, the name and email address they confirm to us. We do not receive your password from them.
What you tell us during onboarding
- Whether you work in-house, at an agency or at a brand; the areas you focus on; your team-size band; and anything you type into the free-text answer.
We use these to understand who Keny is for. They are answers you type, not behaviour we observe.
What you put into a workspace
- Brands, campaigns, phases, beats, directives, briefs and notes.
- Files you upload, such as campaign assets and brand logos. These go into private storage and are served only through short-lived signed links.
- An activity log of which member changed which campaign item, and when. It records campaign edits so a team can see what moved. It is not a keystroke log.
People who are not Keny users
A workspace can hold details of campaign owners who have no Keny account: their name, email address, job role and the organisation they belong to. Whoever created the workspace is the controller of those records and is responsible for telling those people. If you have been named in a workspace this way and want to know more or be removed, write to privacy@keny.io and we will identify the workspace owner and pass your request to them.
Technical data
- Our hosting and database providers keep ordinary server logs, which include your IP address, for security and reliability.
- The sign-in page runs a Cloudflare bot check, which sees your IP address and some browser characteristics. It is there to stop automated attacks on the sign-in form.
What we do not do
- No advertising, ad networks or ad pixels.
- No product analytics, heatmaps, rage-click capture or A/B testing tools.
- No session replay. Nothing records your screen, your typing or your mouse.
- No tracking cookies, and no third-party cookies of any kind.
- No remote fonts. Every font is served from our own domain, so reading these pages does not disclose your IP address to anyone else.
- No selling or sharing of personal data for advertising, under any US state law definition. We have never done this.
- No automated decision-making with a legal or similarly significant effect.
Storage on your device
Keny does not use cookies for tracking. The app keeps a small amount of data in your browser's local storage, all of it strictly necessary to run the service you asked for, which is why no consent banner is shown:
| What | Why |
|---|---|
| Your sign-in session | Keeps you signed in between visits. Set by our authentication provider. |
| Active workspace | Reopens the workspace you were last in. |
| Pending join or invitation | Resumes joining a workspace after you sign in. |
| Share-link password | Saves you retyping it on a view-only share link. |
| Notification preferences | Remembers the choices you made in settings. |
| Onboarding hand-off | Carries the first brand and owner you set up in onboarding into the app, then is cleared. |
| Display choices | Remembers small view choices, such as tinted owner cards. |
Clearing your browser data removes all of it and signs you out.
Why we are allowed to use it
| Purpose | Lawful basis |
|---|---|
| Running your account and the service | Performance of a contract |
| Keeping the service secure, including the bot check | Legitimate interests: preventing abuse and attacks |
| Occasional product email to account holders | Legitimate interests. You can ask us to stop at any time |
| Understanding who Keny is for, from onboarding answers | Legitimate interests: improving the product |
| Meeting our legal obligations | Legal obligation |
Where we rely on legitimate interests you can object at any time, using the contact details above.
We send two kinds of email, and treat them differently on purpose.
- Account email, such as workspace invitations, password resets and address-change confirmations. These go out because someone acted, they contain no marketing, and they have no unsubscribe control, because switching them off would stop you getting into your own account.
- Product email, such as the welcome note after you sign up. To stop these, write to privacy@keny.io and we will stop sending them to you.
Who else sees it
Other members of your workspace see the content you put in it and your name against your changes. Beyond that, data reaches only the processors listed on the subprocessors page, each under a written data-processing agreement. We may also disclose data where the law requires it.
Where it is held
Our database, file storage and authentication run in the EU (Paris), with Supabase. Our other processors operate globally. Where personal data leaves the UK or the EEA, the transfer relies on the UK International Data Transfer Addendum and the European Commission's Standard Contractual Clauses.
How long we keep it
- Account and workspace data: while the account exists.
- After you delete your account: removed from live systems straight away, and from routine backups within 7 days.
- Server logs: kept for as long as our hosting providers hold them.
Your rights
Under the UK GDPR and the EU GDPR you may ask for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict or stop a particular use, object to processing based on legitimate interests, and ask for your data in a portable form.
You can delete your whole account yourself, without asking us, in Account settings. It removes your account and your personal data. If you own a workspace with other people in it, hand it over or remove them first, so their work is not deleted along with you.
For anything else, write to privacy@keny.io. We answer within one month.
If you are in the UK you may complain to the Information Commissioner's Office at ico.org.uk. If you are in the EEA you may complain to your national data protection authority. We would rather you came to us first.
If you are in California, Colorado, Connecticut, Virginia or another US state with a comparable law, the rights above cover the access, correction, deletion, portability and opt-out rights those laws give you. We do not sell or share personal data for advertising, so there is no opt-out to offer, and we will not treat you differently for exercising a right.
Children
Keny is a workplace tool and is not for children. You must be 16 or older to use it, as the terms say. We do not knowingly collect data from anyone under 16. If you believe a child has given us data, write to privacy@keny.io and we will delete it.
Changes
If we change this policy in a way that matters, we will email account holders before it takes effect. The date at the top always shows the current version.
Privacy contact
Yoav Cabili, trading as Keny
privacy@keny.io